• Specify the group number to be used.
• Not specifying a group number displays the current setting.
ISAKMP SA (phase 1) validity period setting
msh> ipsec ike {1|2|3|4|default} ph1 lifetime validity period
• Enter the separate setting number [1-4] or [default] and specify the ISAKMP SA (phase 1) validity
period.
• Enter the validity period (in seconds) from 300 to 172800.
• Not specifying a validity period displays the current setting.
IPsec SA (phase 2) authentication algorithm setting
msh> ipsec ike {1|2|3|4|default} ph2 auth {hmac-md5|hmac-sha1}
• Enter the separate setting number [1-4] or [default] and specify the IPsec SA (phase 2)
authentication algorithm.
• Separate multiple encryption algorithm entries with a comma (,). The current setting values are
displayed in order of highest priority.
• Not specifying an authentication algorithm displays the current setting.
IPsec SA (phase 2) encryption algorithm setting
msh> ipsec ike {1|2|3|4|default} ph2 encrypt {null|des|3des|aes128|aes192|
aes256}
• Enter the separate setting number [1-4] or [default] and specify the IPsec SA (phase 2) encryption
algorithm.
• Separate multiple encryption algorithm entries with a comma (,). The current setting values are
displayed in order of highest priority.
• Not specifying an encryption algorithm displays the current setting.
IPsec SA (phase 2) PFS setting
msh> ipsec ike {1|2|3|4|default} ph2 pfs {none|1|2|14}
• Enter the separate setting number [1-4] or [default] and specify the IPsec SA (phase 2) Diffie-
Hellman group number.
• Specify the group number to be used.
• Not specifying a group number displays the current setting.
IPsec SA (phase 2) validity period setting
msh> ipsec ike {1|2|3|4|default} ph2 lifetime validity period
• Enter the separate setting number [1-4] or [default] and specify the IPsec SA (phase 2) validity
period.
• Enter the validity period (in seconds) from 300 to 172800.
• Not specifying a validity period displays the current setting.
Transmission Using IPsec
125